43
*** Condential - DO NOT Distribute ***
Director
Command Sub-Command Parameters Example and description
lter add ipv6=< y | n >
in_ports=<network_portlist>*
<qual>=<value>
action=< redir | drop >
redir_ports=<monitor_portlist>
Notes:
The command may include
any number of <qual>, up
to the limit of Director's lter
resources (approximately
1,000 <qual> per chassis)
The action=< redir | drop >
parameter is required
If action=redir, then
redir_ports=<monitor_portlist>
parameter is required
lter add ipv6=n in_ports=n1.1-n1.3 ip_
src=10.1.1.1 action=drop
Parameters:
ipv6=y for IPv6 addressing; ipv6=n for IPv4 ad-
dressing (defaults to IPv4 if parameter is omitted)
<network_portlist> — trafc from the network
ports specied in this portlist is aggregated before
being sent to the lter
<qual> and <value> are lter qualiers and values
as listed in the table that follows this table
Specify redir or drop as the lter action —
if redir, packets matching all of the <qual> are
copied to all of the Monitor ports specied in the
portlist <monitor_portlist>
if drop, packets matching all of the <qual> are
dropped
Denes a lter, including the Network and Monitor
ports involved in the lter; lter is pending (inactive)
until activated by a lter commit or commit command
Note: If the lter command does not include any
<qual>, it denes aggregation, regeneration, and
matrix switching functions without ltering
clear lter clear
Clears all active lters
commit lter commit
Activates pending lters previously dened using
lter add and lter ins commands
del ipv6=< y | n >
id=<id>*
lter del id=3
Parameters:
ipv6=y for IPv6 addressing; ipv6=n for IPv4 ad-
dressing (defaults to IPv4 if parameter is omitted)
<id> is a decimal number from 1 to 999 that
identies which lter is to be deleted
Deletes a pending lter
discard lter discard
Clears all pending lters
ins ipv6=< y | n >
id=<id>*
in_ports=<network_portlist>
<qual>=<value>
action=< redir | drop >
redir_ports=<monitor_portlist>
lter ins id=mylter-1 in_ports=n1.1-n1.3 ip_
src=10.1.1.1 action=drop
Parameters:
ipv6=y for IPv6 addressing; ipv6=n for IPv4 ad-
dressing (defaults to IPv4 if parameter is omitted)
<id> is a decimal number from 1 to 999 that
species the priority of this lter (the address for
the lter in the lter CAM)
The rest of the lters parameters are as dened
for the lter add command
Denes and prioritizes a lter
Comments to this Manuals